<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Firepower cluster dc-dr in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firepower-cluster-dc-dr/m-p/5128662#M1113483</link>
    <description>&lt;P&gt;I think I had the same problem trying to deploy the exact scenario (four clustered FPR 4100 and 2 DCs). Cluster was extended between DCs, having the control role on one DC and setting a different site-ID on every DC, that is FPRs on DC had site-ID 1 and and FPRs on the other DC had site-ID 2. Having just one DC active everything was working fine, although several MAC flapping messages are showing on the Nexus switches, from the connectivity standpoint nothing happens, however the when the second DC was added to the equation everything was impacted and degraded,&lt;/P&gt;
&lt;P&gt;I´ve been testing in a reduced scenario setting a different site-ID (1 to 4) on every FPR, regardless the DC location and it looks like the flapping messages has gone, so I guess it´s not necessary to filter the MAC movement messages, since they´re not showing anymore&lt;/P&gt;
&lt;P&gt;Would you mind to share what solution was offered by the TAC? I´ve engaged them to help on this matter but so so far no luck...&lt;/P&gt;
&lt;P&gt;Thank you very much&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Iván&lt;/P&gt;</description>
    <pubDate>Tue, 11 Jun 2024 17:41:08 GMT</pubDate>
    <dc:creator>kimier1983</dc:creator>
    <dc:date>2024-06-11T17:41:08Z</dc:date>
    <item>
      <title>Firepower cluster dc-dr</title>
      <link>https://community.cisco.com/t5/network-security/firepower-cluster-dc-dr/m-p/4588511#M1089039</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a firepower cluster, 2 on DC and 2 on DR connected through a nexus switch&amp;nbsp; ( dark fiber) , i am getting mac flapping on the nexus , the Site ID on the chassis is both different.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can anyone advise please&lt;/P&gt;</description>
      <pubDate>Thu, 07 Apr 2022 17:14:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-cluster-dc-dr/m-p/4588511#M1089039</guid>
      <dc:creator>ashleybabajee</dc:creator>
      <dc:date>2022-04-07T17:14:15Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower cluster dc-dr</title>
      <link>https://community.cisco.com/t5/network-security/firepower-cluster-dc-dr/m-p/4588522#M1089041</link>
      <description>&lt;P&gt;Can you share a diagram of your setup?&lt;/P&gt;
&lt;P&gt;Are the Nexus' in a VPC configuration?&lt;/P&gt;</description>
      <pubDate>Thu, 07 Apr 2022 17:58:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-cluster-dc-dr/m-p/4588522#M1089041</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2022-04-07T17:58:45Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower cluster dc-dr</title>
      <link>https://community.cisco.com/t5/network-security/firepower-cluster-dc-dr/m-p/4588855#M1089052</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/326046"&gt;@Marvin Rhoads&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes they are in a vpc configuration&lt;/P&gt;</description>
      <pubDate>Fri, 08 Apr 2022 05:35:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-cluster-dc-dr/m-p/4588855#M1089052</guid>
      <dc:creator>ashleybabajee</dc:creator>
      <dc:date>2022-04-08T05:35:20Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower cluster dc-dr</title>
      <link>https://community.cisco.com/t5/network-security/firepower-cluster-dc-dr/m-p/4591740#M1089187</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/326046"&gt;@Marvin Rhoads&lt;/a&gt; , any idea ?, i have already uploaded the diagram, grateful to advise.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Apr 2022 11:10:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-cluster-dc-dr/m-p/4591740#M1089187</guid>
      <dc:creator>ashleybabajee</dc:creator>
      <dc:date>2022-04-13T11:10:30Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower cluster dc-dr</title>
      <link>https://community.cisco.com/t5/network-security/firepower-cluster-dc-dr/m-p/4592047#M1089202</link>
      <description>&lt;P&gt;Are all four firewalls in a single cluster?&lt;/P&gt;
&lt;P&gt;Are there vPCs between the Nexus switches?&lt;/P&gt;</description>
      <pubDate>Wed, 13 Apr 2022 17:36:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-cluster-dc-dr/m-p/4592047#M1089202</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2022-04-13T17:36:02Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower cluster dc-dr</title>
      <link>https://community.cisco.com/t5/network-security/firepower-cluster-dc-dr/m-p/4592382#M1089220</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/326046"&gt;@Marvin Rhoads&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, all the firewall are in the same cluster, and yes there's vPV between the Nexus.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Apr 2022 06:49:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-cluster-dc-dr/m-p/4592382#M1089220</guid>
      <dc:creator>ashleybabajee</dc:creator>
      <dc:date>2022-04-14T06:49:49Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower cluster dc-dr</title>
      <link>https://community.cisco.com/t5/network-security/firepower-cluster-dc-dr/m-p/4594122#M1089288</link>
      <description>&lt;P&gt;If I understand it correctly you are using what Cisco calls "Split Spanned Etherchannel Cluster". They mention in Cisco Live presentation BRKSEC-3032 that filtering is required is such a use case to avoid MAC/IP conflicts.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="FTD Cluster with Split Spanned Etherchannel.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/149130i08B9A886C2DBD55A/image-size/large?v=v2&amp;amp;px=999" role="button" title="FTD Cluster with Split Spanned Etherchannel.PNG" alt="FTD Cluster with Split Spanned Etherchannel.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 17 Apr 2022 12:02:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-cluster-dc-dr/m-p/4594122#M1089288</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2022-04-17T12:02:40Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower cluster dc-dr</title>
      <link>https://community.cisco.com/t5/network-security/firepower-cluster-dc-dr/m-p/4594417#M1089290</link>
      <description>&lt;P&gt;I have applied mac acl on the HO nexus , but still same issue , there's a port-channel/vPC between the HO and DR Nexus, when one link is up it works fine, however when both links are up, we get the mac flap issues.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Apr 2022 12:18:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-cluster-dc-dr/m-p/4594417#M1089290</guid>
      <dc:creator>ashleybabajee</dc:creator>
      <dc:date>2022-04-18T12:18:23Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower cluster dc-dr</title>
      <link>https://community.cisco.com/t5/network-security/firepower-cluster-dc-dr/m-p/4594425#M1089292</link>
      <description>&lt;P&gt;That's odd. I'd suggest opening a TAC case so that the engineer can work with you in real time to trace the root cause.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Apr 2022 12:31:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-cluster-dc-dr/m-p/4594425#M1089292</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2022-04-18T12:31:12Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower cluster dc-dr</title>
      <link>https://community.cisco.com/t5/network-security/firepower-cluster-dc-dr/m-p/5128662#M1113483</link>
      <description>&lt;P&gt;I think I had the same problem trying to deploy the exact scenario (four clustered FPR 4100 and 2 DCs). Cluster was extended between DCs, having the control role on one DC and setting a different site-ID on every DC, that is FPRs on DC had site-ID 1 and and FPRs on the other DC had site-ID 2. Having just one DC active everything was working fine, although several MAC flapping messages are showing on the Nexus switches, from the connectivity standpoint nothing happens, however the when the second DC was added to the equation everything was impacted and degraded,&lt;/P&gt;
&lt;P&gt;I´ve been testing in a reduced scenario setting a different site-ID (1 to 4) on every FPR, regardless the DC location and it looks like the flapping messages has gone, so I guess it´s not necessary to filter the MAC movement messages, since they´re not showing anymore&lt;/P&gt;
&lt;P&gt;Would you mind to share what solution was offered by the TAC? I´ve engaged them to help on this matter but so so far no luck...&lt;/P&gt;
&lt;P&gt;Thank you very much&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Iván&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jun 2024 17:41:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-cluster-dc-dr/m-p/5128662#M1113483</guid>
      <dc:creator>kimier1983</dc:creator>
      <dc:date>2024-06-11T17:41:08Z</dc:date>
    </item>
  </channel>
</rss>

